STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.

DISA Rule

SV-220344r960882_rule

Vulnerability Number

V-220344

Group Title

SRG-APP-000090-DB-000065

Rule Version

ML09-00-000600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DBMS's settings to allow designated personnel to select which auditable events are audited.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Roles assigned to the Users. For designated personnel, assign the admin role and change user roles as necessary.
4. Inspect the Roles assigned to the Users. For non-designated personnel, remove the admin role and change user roles as necessary.

Check Contents

Check MarkLogic settings and documentation to determine whether designated personnel are able to select which auditable events are being audited.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Roles assigned to the Users. If a User who is designated personnel does not have the admin role, this is a finding.
4. Inspect the Roles assigned to the Users. If a User who is not designated personnel has the admin role, this is a finding.

Vulnerability Number

V-220344

Documentable

False

Rule Version

ML09-00-000600

Severity Override Guidance

Check MarkLogic settings and documentation to determine whether designated personnel are able to select which auditable events are being audited.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Roles assigned to the Users. If a User who is designated personnel does not have the admin role, this is a finding.
4. Inspect the Roles assigned to the Users. If a User who is not designated personnel has the admin role, this is a finding.

Check Content Reference

M

Target Key

4064